


Perceptive Security
SOC/SIEM Consultancy

SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenate…
Published:
2 August 2026 at 22:00:00
Alert date:
3 August 2026 at 15:06:10
Source:
nvd.nist.gov
Web Technologies, Database & Storage, Zero-Day Vulnerabilities
SiYuan versions before v3.7.3 contain a SQL injection vulnerability in the /api/filetree/searchDocs endpoint. The keyword parameter is directly concatenated into SQL queries without escaping or parameterized binding. The vulnerability is exploitable by users with a publish RoleReader token, or entirely unauthenticated when publish mode is enabled with Publish.Auth.Enable set to false. The underlying SQLite handle is read-write and the driver supports stacked (semicolon-separated) statements, allowing attackers to both read and modify database content. All cleartext (non-encrypted) notebooks on the affected instance are at risk. The fix was introduced in SiYuan v3.7.3. This vulnerability has been documented by NVD, GitHub Security Advisories, and VulnCheck.
Technical details
Mitigation steps:
Affected products:
SiYuan before v3.7.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-69085
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-33jq-p8c2-q3q4
https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-searchdocs
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
